Security

cPanel bug left gov.uk website exposed to attacker takeover

A flaw in the UK's Eastern Inshore Fisheries and Conservation Authorities (IFCA) website could’ve allowed attackers to carry out a complete user account takeover. And in some cases even leading to threat actors appropriating control of the UK government website.
Read more about cPanel bug left gov.uk website exposed to attacker takeover

Rock Tsai, Taiwan Mobile: “the most significant cyberthreat that organizations face today is social engineering attacks”

Cybercriminals have found ways to exploit social engineering techniques, infiltrating systems that directly impact the supply chain and financial industry....
Read more about Rock Tsai, Taiwan Mobile: “the most significant cyberthreat that organizations face today is social engineering attacks”

Lisa Sicard, Inspire To Thrive: “the biggest challenge in the digital marketing realm is staying on top of the rapid changes”

Digital content and marketing platforms today have slowly begun to integrate more convenient AI tools. Of course, keeping up with...
Read more about Lisa Sicard, Inspire To Thrive: “the biggest challenge in the digital marketing realm is staying on top of the rapid changes”

Manufacturing exposed: over half of IT managers tackling costly ransomware attacks

Ransomware attacks in manufacturing and production have crept up to a level where 56% of IT and cybersecurity managers must address ransomware attacks within a year, the newest Sophos 2023 Threat Report shows.
Read more about Manufacturing exposed: over half of IT managers tackling costly ransomware attacks

Selfies and passports of Philippine police exposed in data leak

A misconfiguration in the systems of the Philippine National Police caused a significant data leak and put its officers at risk.
Read more about Selfies and passports of Philippine police exposed in data leak

Microsoft denies claims of data breach

Microsoft said there was no evidence of its user data being accessed or compromised.
Read more about Microsoft denies claims of data breach

Hacker sets up Tor-based online shop to sell access to firms

A new threat actor has started selling access to major companies worldwide. What makes Br0k3r stand out, however, is that it’s one of the first to trade access through its own website.
Read more about Hacker sets up Tor-based online shop to sell access to firms

Who is 8BASE? A deep dive into the "newish" ransom gang

A new ransomware group – known as 8BASE – is already making waves this summer following a record number of victims named in May. Cybernews takes you on a deep dive into what we know about the gang so far.
Read more about Who is 8BASE? A deep dive into the "newish" ransom gang

Top 5 cyber threat actors of 2023

Come with us as we peel back the digital curtain, uncovering the operations, techniques, and impact of five highly active and clandestine groups causing significant disruptions across the cyber landscape.
Read more about Top 5 cyber threat actors of 2023

Clop names PWC, Ernst & Young, and Sony in MOVEit hack

The Cl0p ransom gang has released the names of four new victims in the MOVEit hacking spree – including multi-media conglomerate Sony, and two major accounting firms, PricewaterhouseCoopers (PWC) and Ernst & Young (EY).
Read more about Clop names PWC, Ernst & Young, and Sony in MOVEit hack

Google pledges $20M to expand free cybersecurity clinics across US

Google is pledging $20 million to open more hands-on cybersecurity clinics across the US in an effort to help plug the nation’s cybersecurity workforce gap and stay ahead of evolving threats.
Read more about Google pledges $20M to expand free cybersecurity clinics across US

Global development corp IFC hacked near White House

The Russian-allied hacktivist gangs Killnet and Anonymous Sudan have claimed another major financial institution — the International Finance Corporation (IFC) headquartered in Washington DC.
Read more about Global development corp IFC hacked near White House

Minecraft server host Shockbyte puts players at risk

Shockbyte, one of Minecraft’s largest server hosting providers, left a misconfiguration on its systems exposing it to threat actors that could potentially have manipulated Minecraft server code.
Read more about Minecraft server host Shockbyte puts players at risk

Honda ecommerce platform vulnerability: a walkthrough

Honda was exposed to a critical security risk due to a vulnerability in its API. How did the exploit work?
Read more about Honda ecommerce platform vulnerability: a walkthrough

DoJ creates new National Security Cyber Section

The US National Security Division (NSD) now has its own Cyber Section, created so the agency can better respond to highly technical cyber threats.
Read more about DoJ creates new National Security Cyber Section

Compromised ChatGPT accounts are for sale on dark web

Over 100,000 ChatGPT credentials are currently being traded on the dark market. Given that employees increasingly rely on AI to boost productivity, the compromised credentials could lead threat actors to a treasure trove of data.
Read more about Compromised ChatGPT accounts are for sale on dark web

Square Yards data leak: passports, financial data exposed

India’s largest real estate platform has exposed nearly 350M files, including customer and employee passports and financial documents.
Read more about Square Yards data leak: passports, financial data exposed

Third MOVEit flaw identified by CISA, patch now

A new security advisory is warning organizations to immediately patch a third critical vulnerability found in the MOVEit file transfer system.
Read more about Third MOVEit flaw identified by CISA, patch now

Darknet Parliament is now a thing

The newly coined term “Darknet Parliament” has become the latest catchphrase among cybercriminals trying to prove their clout – and security insiders are loving it.
Read more about Darknet Parliament is now a thing

Swiss Financial Center knocked offline by Russian hackers

The pro-Russian hacker group responsible for a string of attacks against Switzerland's critical infrastructure this week has now hit the website of the Geneva financial center.
Read more about Swiss Financial Center knocked offline by Russian hackers